Discussion:
[conspire] Experian insecurity ...
Michael Paoli
2018-11-29 08:29:58 UTC
Permalink
Way to go Experian insecurity <sigh>.
Will they never learn?
Me: picks nice secure 20 character password
Them: "Password is too long."
Me: ... 19 characters ...
Them: "Password is too long."
...
16 ... too long
15 ... the damn registration thingy still fails anyway.

There's no good reason to limit password/passphrase lengths ...
especially to anything rather to quite short. After all, what should
be getting stored is
only a secure hash of such, so that will be same length regardless of
password/passphrase length.

Yeah, still, far too many sites, etc., don't properly do/handle
passwords/passphrases.

Ah well, ... at least they have toll free number, and should eventually get
back to me (they tried to fix their basic brokenness on the phone but
were unable to).
Rick Moen
2018-11-29 10:35:42 UTC
Permalink
Post by Michael Paoli
Way to go Experian insecurity <sigh>.
Will they never learn?
Me: picks nice secure 20 character password
Them: "Password is too long."
Me: ... 19 characters ...
Them: "Password is too long."
...
16 ... too long
15 ... the damn registration thingy still fails anyway.
{boggle}

Wow, too bad there aren't things like multi-terabyte hard drives in this
world. But good thing Experian doesn't handle any sensitive data.
Post by Michael Paoli
Yeah, still, far too many sites, etc., don't properly do/handle
passwords/passphrases.
I love the ones where you can ask them to mail the password to you,
which means not only that they're cheerfully mailing them around in
plaintext but also storing them that way, ripe for the plucking.

Loading...